What changed on this day
44 changes were tracked across 3 Microsoft Entra products. The leading updates include 21836; 21869; 21830.
Daily.Entra.News44 changes were tracked across 3 Microsoft Entra products. The leading updates include 21836; 21869; 21830.
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
If this check passes, your tenant has a TRv2 policy configured but more steps are required to validate the scenario end-to-end.
Without proper session controls, threat actors can achieve lateral movement across the organization's infrastructure, accessing critical data and systems that extend far beyond the original guest account's intended scope of access.
A Microsoft Entra documentation page was updated: Purview Workload Content Administrator.
A Microsoft Entra documentation page was updated: Purview Workload Content Reader.
A Microsoft Entra documentation page was updated: Purview Workload Content Writer.
- [Define certificate based application configuration](https://devblogs.microsoft.com/identity/app-management-policy/)
The prolonged dormancy of these accounts provides attackers with extended dwell time to conduct reconnaissance, exfiltrate sensitive data, and establish backdoors without detection, as organizations typically focus monitoring efforts on active internal users rather than external guest accounts.
- [Deploy a privileged access workstation solution](/security/privileged-access-workstations/privileged-access-deployment)
Additionally, compromised guest identities can be used to establish credential persistence and potentially escalate privileges. Attackers can exploit trust relationships between guest accounts and internal resources, or use the guest account as a staging ground for lateral movement toward more privileged organizational assets.
In Microsoft Entra ID, if another administrator or nonadministrator needs to manage Microsoft Entra resources, you assign them a Microsoft Entra role that provides the permissions they need. For example, you can assign roles to allow adding or changing users, resetting user passwords, managing user licenses, or managing domain names.
While an application with open assignment but proper provisioning scoping (such as department-based filters or group membership requirements) maintains security controls through the provisioning layer, applications lacking both controls create unrestricted access pathways that threat actors can exploit. When applications provision accounts for all users without assignment restrictions, threat actors can abuse compromised accounts to conduct reconnaissance activities, enumerate sensitive data across multiple systems, or use the applications as staging points for further attacks against connected resources. This unrestricted access model is dangerous for applications that have elevated permissions or are connected to critical business systems. Threat actors can use any compromised user account to access sensitive information, modify data, or perform unauthorized actions that the application's permissions allow. The absence of both assignment controls and provisioning scoping also prevents organizations from implementing proper access governance. Without proper governance, it's difficult to track who has access to which applications, when access was granted, and whether access should be revoked based on role changes or employment status. Furthermore, applications with broad provisioning scopes can create cascading security risks where a single compromised account provides access to an entire ecosystem of connected applications and services.
In Microsoft Entra ID Governance, you can enable business groups to determine which of these guests should have access, and for how long, using:
A Microsoft Entra documentation page was updated: Delegate Approvals My Access.
If administrators assign privileged roles to workload identities, such as service principals or managed identities, the tenant can be exposed to significant risk if those identities are compromised. Threat actors who gain access to a privileged workload identity can perform reconnaissance to enumerate resources, escalate privileges, and manipulate or exfiltrate sensitive data. The attack chain typically begins with credential theft or abuse of a vulnerable application. Next step is privilege escalation through the assigned role, lateral movement across cloud resources, and finally persistence via other role assignments or credential updates. Workload identities are often used in automation and might not be monitored as closely as user accounts. Compromise can then go undetected, allowing threat actors to maintain access and control over critical resources. Workload identities aren't subject to user-centric protections like MFA, making least-privilege assignment and regular review essential.