Week in brief

Conditional Access and token-theft guidance were the week’s meaningful Entra changes

The week of 8 September 2025 was primarily a Microsoft Learn maintenance cycle: 43 updates, three page removals, one new entry, and no Message Center items. The substantive exception was a set of security-guidance edits for Microsoft Entra ID and ID Protection covering MFA and self-service password reset registration, high-risk sign-ins, token protection, and authentication transfer. The CBA and managed-identity changes are mainly documentation and procedure maintenance, while Global Secure Access received an integration-documentation update. Nothing supplied establishes a new feature, preview, general availability release, service-default change, or capability retirement. The lone new record, “Dragon Administrator,” contains no detail beyond its title and cannot be treated as evidence of a launch.

  • Updated Entra ID guidance warns that unprotected MFA and self-service password reset method registration can be intercepted through adversary-in-the-middle attacks or unmanaged devices, allowing an attacker to register their own authentication methods. Related ID Protection guidance says high-risk sign-ins should be restricted through Conditional Access and that high-risk users should be treated as potentially compromised. The planning guidance also reiterates report-only testing before enforcement. These are clar?

  • Updated Entra ID content explains that blocking authentication transfer helps prevent device-token theft and replay by stopping silent authentication on another device or browser. The token-protection guidance describes token binding that uses the intended device’s client key, making the token unusable without that key. The associated Conditional Access page covers restricting device code flow and authentication transfer. The evidence describes security controls; it does not show that either control was newly added

  • A cluster of Microsoft Entra certificate-based authentication pages covering the technical deep dive, certificate user IDs, limitations, migration, mobile platforms, smart cards, and certificate revocation lists was updated. Most supplied summaries add links to the CBA overview or deep-dive material; the revocation-list entry reiterates that a CA-issued certificate remains valid until expiration unless revoked earlier. This supports a navigation and documentation clarification, not a demonstrated CBA behavior or-??

  • Workload ID documentation was updated for granting managed-identity access with PowerShell, Azure CLI, and the portal, including app-role assignment and Azure RBAC context. One update notes that deleting a user-assigned managed identity does not remove references from resources; those references must be removed from the resource itself. Three older pages were removed: “Assign Access Azure Resource,” “Assign App Role Managed Identity,” and “How Manage User Assigned Managed Identities.” The evidence supports page and

  • The updated Global Secure Access integration page describes using preconfigured Microsoft Sentinel workbooks and analytics rules to integrate Global Secure Access telemetry and monitoring. It is recorded as a documentation update, so the evidence supports reviewing the integration procedure but does not establish a new integration launch or general availability milestone.

For Entra administrators

Treat this as a review cycle rather than a documented service rollout. Check that Conditional Access coverage for security-information registration and high-risk sign-ins reflects the updated guidance, and review restrictions for device code flow and authentication transfer where relevant. The Conditional Access planning guidance says template-created policies start in report-only mode and should be tested and monitored before enforcement. Update bookmarks and operational runbooks for CBA and managed identities after the related page changes and removals. Administrators using Global Secure Access with Microsoft Sentinel can review the integration guidance. The supplied records do not support a mandatory rollout or emergency configuration change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

15

21828

Updated

Blocking authentication transfer in Microsoft Entra ID is a critical security control. It helps protect against token theft and replay attacks by preventing the use of device tokens to silently authenticate on other devices or browsers. When authentication transfer is enabled, a threat actor who gains access to one device can access resources to nonapproved devices, bypassing standard authentication and device compliance checks. When administrators block this flow, organizations can ensure that each authentication request must originate from the original device, maintaining the integrity of the device compliance and user session context.

9 September 2025

21781

Updated

- [Get started with a phishing-resistant passwordless authentication deployment](/entra/identity/authentication/how-to-plan-prerequisites-phishing-resistant-passwordless-authentication)

9 September 2025

21782

Updated

- [Get started with a phishing-resistant passwordless authentication deployment](/entra/identity/authentication/how-to-plan-prerequisites-phishing-resistant-passwordless-authentication)

9 September 2025

21783

Updated

- [Get started with a phishing-resistant passwordless authentication deployment](/entra/identity/authentication/how-to-plan-prerequisites-phishing-resistant-passwordless-authentication)

9 September 2025

21800

Updated

- [Deploy multifactor authentication](/entra/identity/authentication/howto-mfa-getstarted)

9 September 2025

21801

Updated

- [Deploy multifactor authentication](/entra/identity/authentication/howto-mfa-getstarted)

9 September 2025
5

Global Administrator

Updated

> | microsoft.hardware.support/shippingAddress/allProperties/allTasks | Create, read, update, and delete shipping addresses for Microsoft hardware warranty claims, including shipping addresses created by others |

12 September 2025

Global Reader

Updated

> | microsoft.hardware.support/shippingAddress/allProperties/read | Read shipping addresses for Microsoft hardware warranty claims, including existing shipping addresses created by others |

12 September 2025

Reply Url

Updated

1. `http` URI schemes are acceptable because the redirect never leaves the device. As such, both of these URIs are acceptable:

10 September 2025
4

21796

Updated

**Remediation action**

9 September 2025

21808

Updated

**Remediation action**

9 September 2025

21851

Updated

**Remediation action**

9 September 2025

21872

Updated

**Remediation action**

9 September 2025
3

21806

Updated

Without Conditional Access policies protecting security information registration, threat actors can exploit unprotected registration flows to compromise authentication methods. When users register multifactor authentication and self-service password reset methods without proper controls, threat actors can intercept these registration sessions through adversary-in-the-middle attacks or exploit unmanaged devices accessing registration from untrusted locations. Once threat actors gain access to an unprotected registration flow, they can register their own authentication methods, effectively hijacking the target's authentication profile. The threat actors can bypass security controls and potentially escalate privileges throughout the environment because they can maintain persistent access by controlling the MFA methods. The compromised authentication methods then become the foundation for lateral movement as threat actors can authenticate as the legitimate user across multiple services and applications.

9 September 2025

Block authentication flows with Conditional Access policy

Updated

The following steps help create Conditional Access policies to restrict how [device code flow](concept-authentication-flows.md#device-code-flow) and [authentication transfer](concept-authentication-flows.md#authentication-transfer) are used within your organization.

9 September 2025

Plan Conditional Access

Updated

Start with a few core Conditional Access policies like the ones that follow. Many policies are available as [Conditional Access policy templates](concept-conditional-access-policy-common.md). By default, each policy created from a template is in report-only mode. Test and monitor usage, to ensure the intended result, before turning on each policy.

9 September 2025
2

21786

Updated

Token protection, also called token binding, helps prevent token theft by making sure a token is usable only from the intended device. Token protection uses cryptography so that without the client device key, no one can use the token.

9 September 2025
2

Use Scim To Provision Users And Groups

Updated

1. When the provisioning cycle begins, the service checks if the current access token is valid and exchanges it for a new token if needed. The access token is provided in each request made to the app and the validity of the request is checked before each request.

13 September 2025

userimpact: High

Updated

Assume high risk users are compromised by threat actors. Without investigation and remediation, threat actors can execute scripts, deploy malicious applications, or manipulate API calls to establish persistence, based on the potentially compromised user's permissions. Threat actors can then exploit misconfigurations or abuse OAuth tokens to move laterally across workloads like documents, SaaS applications, or Azure resources. Threat actors can gain access to sensitive files, customer records, or proprietary code and exfiltrate it to external repositories while maintaining stealth through legitimate cloud services. Finally, threat actors might disrupt operations by modifying configurations, encrypting data for ransom, or using the stolen information for further attacks, resulting in financial, reputational, and regulatory consequences.

9 September 2025
1
1

Accepted Token Versions

Updated

The Microsoft identity platform can issue v1.0 tokens and v2.0 tokens. For more information about these tokens, refer to [Access tokens](/entra/identity-platform/access-tokens).

12 September 2025
1

Uniflow Online Provisioning Tutorial

Updated

This section guides you through the steps to configure the Microsoft Entra provisioning service to create, update, and disable users and/or groups in TestApp based on user and/or group assignments in Microsoft Entra ID.

13 September 2025
1

21799

Updated

When high-risk sign-ins are not properly restricted through Conditional Access policies, organizations expose themselves to security vulnerabilities. Threat actors can exploit these gaps for initial access through compromised credentials, credential stuffing attacks, or anomalous sign-in patterns that Microsoft Entra ID Protection identifies as risky behaviors. Without appropriate restrictions, threat actors who successfully authenticate during high-risk scenarios can perform privilege escalation by misusing the authenticated session to access sensitive resources, modify security configurations, or conduct reconnaissance activities within the environment. Once threat actors establish access through uncontrolled high-risk sign-ins, they can achieve persistence by creating additional accounts, installing backdoors, or modifying authentication policies to maintain long-term access to the organization's resources. The unrestricted access enables threat actors to conduct lateral movement across systems and applications using the authenticated session, potentially accessing sensitive data stores, administrative interfaces, or critical business applications. Finally, threat actors achieve impact through data exfiltration, or compromise business-critical systems while maintaining plausible deniability by exploiting the fact that their risky authentication was not properly challenged or blocked.

9 September 2025
1

Entitlement Management External Users

Updated

When using the [Microsoft Entra B2B](~/external-id/what-is-b2b.md) invite experience, you must already know the email addresses of the external guest users you want to bring into your resource directory and work with. Directly inviting each user works great when you're working on a smaller or short-term project and you already know all the participants. This process is harder to manage if you have lots of users you want to work with, or if the participants change over time. For example, you might be working with another organization and have one point of contact with that organization, but over time more users from that organization will also need access.

10 September 2025
1

Permissions Reference

Updated

> | [Directory Synchronization Accounts](#directory-synchronization-accounts) | Only used by Microsoft Entra Connect service. | d29b2b05-8046-44ba-8758-1e26182fcf32 |

12 September 2025
4

Manage User Assigned Managed Identities Azure Cli

Updated

Deleting a user-assigned managed identity won't remove the reference from any resource it was assigned to. Remove those from the resource itself. For example, for a VM or virtual machine scale set, use the `az vm/vmss identity remove` command.

11 September 2025
3

Grant Managed Identity Resource Access Azure Portal

Updated

The steps outlined below show how you grant access to a service using Azure RBAC. Check specific service documentation on how to grant access; for example, check [Azure Data Explorer](/azure/data-explorer/data-explorer-overview) for instructions. Some Azure services are in the process of adopting Azure RBAC on the data plane.

11 September 2025
2
1