← Previous day

Next day →
Plain-English daily brief

What changed on this day

44 changes were tracked across 3 Microsoft Entra products. The leading updates include 21836; 21869; 21830.

44 updates

Troubleshooting

27

21790

Updated

**Remediation action**

21804

Updated

**Remediation action**

21806

Updated

**Remediation action**

21884

Updated

**Remediation action**

21985

Updated

**Remediation action**

21817

Updated

**Remediation action**

21825

Updated

**Remediation action**

21776

Updated

**Remediation action**

21777

Updated

**Remediation action**

21786

Updated

**Remediation action**

21798

Updated

**Remediation action**

21799

Updated

**Remediation action**

21802

Updated

**Remediation action**

21812

Updated

**Remediation action**

21818

Updated

**Remediation action**

21828

Updated

**Remediation action**

21847

Updated

**Remediation action**

21865

Updated

**Remediation action**

21867

Updated

**Remediation action**

21868

Updated

**Remediation action**

21870

Updated

**Remediation action**

21877

Updated

**Remediation action**

21883

Updated

**Remediation action**

21886

Updated

**Remediation action**

21891

Updated

**Remediation action**

22128

Updated

**Remediation action**

22659

Updated

**Remediation action**

General

8

21793

Updated

If this check passes, your tenant has a TRv2 policy configured but more steps are required to validate the scenario end-to-end.

21824

Updated

Without proper session controls, threat actors can achieve lateral movement across the organization's infrastructure, accessing critical data and systems that extend far beyond the original guest account's intended scope of access.

Monitoring

2

21773

Updated

- [Define certificate based application configuration](https://devblogs.microsoft.com/identity/app-management-policy/)

21858

Updated

The prolonged dormancy of these accounts provides attackers with extended dwell time to conduct reconnaissance, exfiltrate sensitive data, and establish backdoors without detection, as organizations typically focus monitoring efforts on active internal users rather than external guest accounts.

Security

2

21830

Updated

- [Deploy a privileged access workstation solution](/security/privileged-access-workstations/privileged-access-deployment)

21823

Updated

Additionally, compromised guest identities can be used to establish credential persistence and potentially escalate privileges. Attackers can exploit trust relationships between guest accounts and internal resources, or use the guest account as a staging ground for lateral movement toward more privileged organizational assets.

Authentication

1

Microsoft Entra built-in roles

Updated

In Microsoft Entra ID, if another administrator or nonadministrator needs to manage Microsoft Entra resources, you assign them a Microsoft Entra role that provides the permissions they need. For example, you can assign roles to allow adding or changing users, resetting user passwords, managing user licenses, or managing domain names.

Governance

1

21869

Updated

While an application with open assignment but proper provisioning scoping (such as department-based filters or group membership requirements) maintains security controls through the provisioning layer, applications lacking both controls create unrestricted access pathways that threat actors can exploit. When applications provision accounts for all users without assignment restrictions, threat actors can abuse compromised accounts to conduct reconnaissance activities, enumerate sensitive data across multiple systems, or use the applications as staging points for further attacks against connected resources. This unrestricted access model is dangerous for applications that have elevated permissions or are connected to critical business systems. Threat actors can use any compromised user account to access sensitive information, modify data, or perform unauthorized actions that the application's permissions allow. The absence of both assignment controls and provisioning scoping also prevents organizations from implementing proper access governance. Without proper governance, it's difficult to track who has access to which applications, when access was granted, and whether access should be revoked based on role changes or employment status. Furthermore, applications with broad provisioning scopes can create cascading security risks where a single compromised account provides access to an entire ecosystem of connected applications and services.

Fundamentals

1

Identity Governance Overview

Updated

In Microsoft Entra ID Governance, you can enable business groups to determine which of these guests should have access, and for how long, using:

Governance

1

Monitoring

1

21836

Updated

If administrators assign privileged roles to workload identities, such as service principals or managed identities, the tenant can be exposed to significant risk if those identities are compromised. Threat actors who gain access to a privileged workload identity can perform reconnaissance to enumerate resources, escalate privileges, and manipulate or exfiltrate sensitive data. The attack chain typically begins with credential theft or abuse of a vulnerable application. Next step is privilege escalation through the assigned role, lateral movement across cloud resources, and finally persistence via other role assignments or credential updates. Workload identities are often used in automation and might not be monitored as closely as user accounts. Compromise can then go undetected, allowing threat actors to maintain access and control over critical resources. Workload identities aren't subject to user-centric protections like MFA, making least-privilege assignment and regular review essential.