What changed on this day
12 changes were tracked across 4 Microsoft Entra products. The leading updates include userimpact: Low; Security Customers; Policy Migration Mfa.
Daily.Entra.News12 changes were tracked across 4 Microsoft Entra products. The leading updates include userimpact: Low; Security Customers; Policy Migration Mfa.
author: MicrosoftGuyJFlo
Global Administrators with persistent access to Azure subscriptions expand the attack surface for threat actors. If a Global Administrator account is compromised, attackers can immediately enumerate resources, modify configurations, assign roles, and exfiltrate sensitive data across all subscriptions. Requiring just-in-time elevation for subscription access introduces detectable signals, slows attacker velocity, and routes high-impact operations through observable control points.
- Azure Government
Learn how conditions are used in Microsoft Entra Conditional Access to trigger a policy.
Unmaintained or orphaned redirect URIs in app registrations create significant security vulnerabilities when they reference domains that no longer point to active resources. Threat actors can exploit these "dangling" DNS entries by provisioning resources at abandoned domains, effectively taking control of redirect endpoints. This vulnerability enables attackers to intercept authentication tokens and credentials during OAuth 2.0 flows, which can lead to unauthorized access, session hijacking, and potential broader organizational compromise.
author: MicrosoftGuyJFlo
Learn how Microsoft Entra ID is licensed for guest users.
- To review Azure resource or Microsoft Entra roles, see [Create an access review of Azure resource and Microsoft Entra roles in Privileged Identity Management](privileged-identity-management/pim-create-roles-and-resource-roles-review.md).
This article describes shows the licensing requirements for Microsoft Entra ID Governance features.
Administrators can assign a Conditional Access policy to cloud apps from Microsoft as long as the service principal appears in their tenant. Some apps like [Office 365](#office-365) and [Windows Azure Service Management API](#windows-azure-service-management-api) include multiple related child apps or services. When new supported Microsoft cloud applications are created, they appear in the app picker list.