← Previous day

Next day →
Plain-English daily brief

What changed on this day

64 changes were tracked across 5 Microsoft Entra products. The leading updates include Security Service Edge (SSE) Coexistence With Microsoft and Netskope; Retire Service Principal Less Authentication; Security Best Practices For App Registration.

64 updates

General

17

Kontiki Tutorial

Removed

A Microsoft Entra documentation page was updated: Kontiki Tutorial.

Promapp Tutorial

Removed

A Microsoft Entra documentation page was updated: Promapp Tutorial.

Authentication

9

Developer

8

Microsoft identity platform

4

Whats New Docs

Updated

Welcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.

Fundamentals

3

Security

3

Provisioning

2

Troubleshooting

2

Identifier Uri Restrictions

Updated

```Failed to add identifier URI {uri}. All newly added URIs must contain a tenant verified domain, tenant ID, or app ID, as per the default tenant policy of your organization. See https://aka.ms/identifier-uri-addition-error for more information on this error.```

Conditional Access

1

Governance

1

Fundamentals

1

Security Features in External Tenants

Updated

Learn about security features and fundamentals for Microsoft Entra External ID customer identity and access management (CIAM) in external tenant configurations.

General

4

Netskope Coexistence

Updated

1. **[Configuration 1: Microsoft Entra Private Access with Netskope Internet Access](#configuration-1-microsoft-entra-private-access-with-netskope-internet-access)**

Fundamentals

1

Add Intune device compliance bypasses to Global Secure Access Internet Access

Updated

The [Universal Conditional Access documentation](/entra/global-secure-access/concept-universal-conditional-access#known-tunnel-authorization-limitations) notes that Global Secure Access has tunnel authorization limitations. This means that you can block access to a forwarding profile in Conditional Access and inadvertently lock users out from accessing anything on their machine.

Security

1

Authentication

2

userimpact: Low

Updated

Microsoft services applications that operate in your tenant are identified as service principals with the owner organization ID "f8cdef31-a31e-4b4a-93e4-5f571e91255a". When these service principals have credentials configured in your tenant, they might create potential attack vectors that threat actors can exploit. If the credentials were added by an administrator and are no longer needed, they can become a target for attackers. Although less likely when proper preventive and detective controls are in place on privileged activities, credentials can also be added maliciously by threat actors. In either case, threat actors can use these credentials to authenticate as the service principal, gaining the same permissions and access rights as the Microsoft service application. This initial access can lead to privilege escalation if the application has high-level permissions, allowing lateral movement across the tenant. Attackers can then proceed to data exfiltration or persistence establishment through creating additional backdoor credentials.

General

1

Fundamentals

4